Privacy Policy

Last updated: 30 August 2026

This policy explains what personal data Cupidera collects, why, on what legal basis, who sees it, how long we keep it, and what you can do about it. It applies to cupidera.com and to your Cupidera account.

1. Who is responsible

The controller of your personal data is:

  • Cupidera OÜ, registry code 17553967 (Estonian Commercial Register)
  • Vesivärava tn 50, Kesklinna linnaosa, Tallinn, Harju maakond 10152, Estonia
  • Privacy enquiries: privacy@cupidera.com
  • General: info@cupidera.com

2. The sensitive part, stated plainly

Cupidera is a dating service. When you tell us your own gender and the gender you are looking for, those two facts together can reveal your sexual orientation. Under the GDPR that is a special category of personal data (Article 9), which gets stronger protection.

We process it on the basis of your explicit consent, which you give when you create your profile. Consent is the only realistic basis for this — the GDPR does not allow “necessary for a contract” to be used for special category data.

You can withdraw that consent at any time. Withdrawing it means we can no longer run a dating profile for you, so it will end your account; it does not affect anything we did lawfully before you withdrew, and it is not a breach of contract by you. Withdrawing is as easy as giving: write to privacy@cupidera.com or use Settings → Delete Account.

Your photos are not treated as biometric data, because we do not run facial recognition or face matching on them.

3. What we collect and why

Data Why Legal basis
Username, first and last name, email address, password (stored hashed) To create and secure your account Performance of the contract, Art. 6(1)(b)
Date of birth To confirm you are 18 or older, and to show your age Contract, Art. 6(1)(b); legal obligation to keep the service adult-only, Art. 6(1)(c)
Gender, gender sought, relationship goal To match you with other members Contract, Art. 6(1)(b) and explicit consent, Art. 9(2)(a)
Country, region, city, and — only if you turn it on — approximate location for “Near Me” To show you members nearby Contract, Art. 6(1)(b); consent for precise location
Profile answers (appearance, lifestyle, education, religion, ethnicity, marital status, children, income and similar) To build your profile and power search filters. These are optional Consent, Art. 6(1)(a); explicit consent, Art. 9(2)(a), where an answer reveals religion, health or ethnic origin
Photos, albums, audio and video you upload To display your profile Contract, Art. 6(1)(b)
Messages, winks, gifts, Meet Me choices, favourites, friends, blocks, profile views To operate the features you use Contract, Art. 6(1)(b)
Arrow purchases, balance, spending history, invoices To sell and account for Arrows Contract, Art. 6(1)(b); legal obligation (accounting and tax), Art. 6(1)(c)
IP address, browser and device information, log and security data Security, fraud and abuse prevention, keeping the service working Legitimate interests, Art. 6(1)(f) — running a safe platform
Reports you make or that are made about you, moderation decisions Member safety and legal compliance Legitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c); Art. 9(2)(f) for legal claims
Record of your consents: age and terms confirmation, timestamp, IP address, policy version To be able to demonstrate consent, as the GDPR requires Legal obligation, Art. 6(1)(c)
Marketing preferences To send you updates if you asked for them Consent, Art. 6(1)(a)

Providing the data marked as necessary for the contract is required to have an account; without it we cannot provide the Service. Optional profile answers are exactly that — optional.

4. What other members see

Your profile — username, age, gender, location, photos and the profile answers you chose to fill in — is visible to other logged-in members. It is not published to the open internet and is not indexed by search engines.

You control more of this than you might think, in Settings → Privacy: you can make your profile private, hide it entirely with stealth mode, restrict who sees your photos, friends, audio and video, and block individual members.

Messages are private between you and the recipient, subject to moderation where a report is made.

5. Who else receives your data

We do not sell your personal data. We share it only with:

  • Our hosting provider, which stores the site and database on servers in the European Union;
  • Payment providers, when you buy Arrows — they receive what they need to take the payment. We never see or store your full card number;
  • Email delivery, to send account and transactional messages;
  • Our accountants and auditors, for invoices and bookkeeping;
  • Law enforcement, courts and regulators, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend a legal claim.

Anyone processing data on our behalf does so under a written data processing agreement, only on our instructions.

6. Transfers outside the EU/EEA

We keep your data in the European Union wherever we can. If a provider we use processes data outside the EU/EEA, we rely on one of:

  • an adequacy decision of the European Commission for that country; or
  • the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914), together with an assessment of the laws of the destination country and any additional safeguards needed.

You can ask us for a copy of the safeguards in place by writing to privacy@cupidera.com.

7. How long we keep things

Your account, profile, photos and messages While your account is open
After you delete your account Deleted or anonymised without undue delay, other than the items below
Invoices and accounting records 7 years from the end of the financial year in which the transaction was recorded — required by the Estonian Accounting Act
Consent records (age, terms) As long as needed to demonstrate compliance and to defend legal claims
Reports, moderation decisions and safety records Up to 3 years, or longer where a legal claim or investigation is ongoing
Security and access logs Up to 12 months

If you die: under Estonian law your consent remains valid for 10 years after death unless you decided otherwise. Your heir can ask us to close the account and erase the data at any time within that period, by writing to privacy@cupidera.com. You can tell us your own wishes in advance and we will follow them.

8. Your rights

You can:

  • Access your data and get a copy (Art. 15);
  • Correct anything inaccurate (Art. 16) — most of it directly in Edit Profile;
  • Erase your data (Art. 17) — Settings → Delete Account, or ask us;
  • Restrict processing (Art. 18);
  • Port your data to another service in a machine-readable format (Art. 20);
  • Object to processing based on legitimate interests (Art. 21) — and object to direct marketing at any time, which we will always honour;
  • Withdraw consent at any time (Art. 7(3)), as easily as you gave it, without affecting the lawfulness of what came before;
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22).

Write to privacy@cupidera.com. We answer within one month, and will tell you if we need longer.

9. Automated processing

Search results, Meet Me suggestions and match ordering are produced automatically from the criteria you and other members set — gender, age range, location and the profile answers you chose. This is straightforward filtering and ranking on your own stated preferences. It does not produce legal effects for you and does not significantly affect you, and there is no profiling used to make decisions about you. Nothing about your account, your access or your price is decided by an algorithm.

10. Security

The site is served over HTTPS. Passwords are stored hashed, never in plain text. Access to production data is limited to the people who need it. We keep the platform and its components updated, and we monitor for abuse.

If a personal data breach occurs and it is likely to result in a risk to you, we notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, and we tell you directly where the risk to you is high.

11. Cookies

See our Cookie Policy. Nothing beyond what is strictly necessary is set before you choose, and you can change your choice at any time from “Cookie settings” in the footer.

12. Children

Cupidera is for adults only. We do not knowingly collect data about anyone under 18. Registrations with a date of birth under 18 are rejected. If you believe a minor is using the Service, tell us at safety@cupidera.com and we will remove the account.

13. Complaints

If you think we have handled your data wrongly, please tell us first at privacy@cupidera.com. You also have the right to complain to a supervisory authority. Ours is:

  • Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
  • Tatari 39, Tallinn 10134, Estonia
  • Telephone: +372 627 4135
  • Email: info@aki.ee
  • Website: www.aki.ee

Submissions to the Inspectorate are normally made in Estonian. You may also complain to the supervisory authority in the EU country where you live or work, or where you believe the problem occurred.

14. Changes

If we change this policy we will post the new version here and update the date at the top. Where a change matters to you, we will tell you by email or in the Service before it takes effect.